CVE-2014-0151

Severity
6.8MEDIUM
EPSS
0.1%
top 68.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 13
Latest updateMay 13

Description

Cross-site request forgery (CSRF) vulnerability in oVirt Engine before 3.5.0 beta2 allows remote attackers to hijack the authentication of users for requests that perform unspecified actions via a REST API request.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-64m5-2h4c-p759: Cross-site request forgery (CSRF) vulnerability in oVirt Engine before 32022-05-13
CVEList
CVE-2014-0151: Cross-site request forgery (CSRF) vulnerability in oVirt Engine before 32015-02-13

📋Vendor Advisories

1
Red Hat
ovirt-engine: cross-site request forgery (CSRF)2014-03-17

💬Community

2
Bugzilla
CVE-2014-0151 ovirt-engine: cross-site request forgery (CSRF)2014-03-28
Bugzilla
CVE-2014-0151 ovirt-engine: ovirt-engine-api: cross-site request forgery (CSRF) [fedora-all]2014-03-28
CVE-2014-0151 (MEDIUM CVSS 6.8) | Cross-site request forgery (CSRF) v | cvebase.io